BetterPrompt

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed BetterPrompt CLI integration, but users should treat generation, uploads, login, and skill installs as deliberate external-service actions.

Install only if you intend to use BetterPrompt as a remote CLI service. Confirm before logging in, sending prompts or local files, generating outputs, installing or updating skills, or removing skills across agents, especially with global scope or wildcard uninstall.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill description is overly broad and encourages activation for general tasks like finding prompt skills, generating outputs, and managing a library. Broad routing language can cause the agent to invoke this skill in many ordinary situations, increasing exposure to risky side effects such as external CLI execution, network access, authentication, and package installation when a narrower skill would suffice.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill instructs the agent to install and uninstall skills into agent environments without pairing those actions with an explicit warning that they modify local or global state. This can lead to silent environment changes, persistence across sessions, and unintended modification of agent behavior, especially if the human did not understand the operational impact.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal